Record summary

CVE-2009-3252 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.

Description

Multiple SQL injection vulnerabilities in news.php in Rock Band CMS 0.10 allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) id parameters.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBRock Band CMS 0.10 - 'news.php' Multiple SQL Injections (2)ExploitDB exploitby AffixNot analyzed1 file
ExploitDB

PoC details
ExploitDBRock Band CMS 0.10 - 'news.php' Multiple SQL Injections (1)ExploitDB exploitby AffixNot analyzed1 file
ExploitDB

PoC details

References

5